tänkte inte på att kolla där men från kl 12:06 så finns det data i loggen men jag vet ju inte vad du vill se…
Date/Time :2006-12-18 12:09:57Severity :MediumReporter :Application MonitorDescription: Application Access Denied (svchost.exe:169.254.175.119:1440)Application: C:\WINDOWS\system32\svchost.exeParent: C:\WINDOWS\system32\services.exeProtocol: UDP InDestination: 169.254.175.119:1440
Date/Time :2006-12-18 12:09:44Severity :MediumReporter :Network MonitorDescription: Outbound Policy Violation (Access Denied, IP = 60.11.125.54, Port = syslog(514))Protocol: UDP OutgoingSource: 255.255.255.255:1280 Destination: 60.11.125.54:syslog(514) Reason: Network Control Rule ID = 53465
Date/Time :2006-12-18 12:09:24Severity :MediumReporter :Network MonitorDescription: Outbound Policy Violation (Access Denied, IP = 217.208.65.212, Port = syslog(514))Protocol: UDP OutgoingSource: 255.255.255.255:1280 Destination: 217.208.65.212:syslog(514) Reason: Network Control Rule ID = 65519
Date/Time :2006-12-18 12:09:22Severity :MediumReporter :Application MonitorDescription: Application Access Denied (svchost.exe:255.255.255.255:bootp(67))Application: C:\WINDOWS\system32\svchost.exeParent: C:\WINDOWS\system32\services.exeProtocol: UDP OutDestination: 255.255.255.255:bootp(67)
Date/Time :2006-12-18 12:09:14Severity :MediumReporter :Network MonitorDescription: Outbound Policy Violation (Access Denied, IP = 217.208.67.52, Port = syslog(514))Protocol: UDP OutgoingSource: 255.255.255.255:1280 Destination: 217.208.67.52:syslog(514) Reason: Network Control Rule ID = 65519
Date/Time :2006-12-18 12:09:14Severity :MediumReporter :Network MonitorDescription: Outbound Policy Violation (Access Denied, IP = 217.208.65.7, Port = syslog(514))Protocol: UDP OutgoingSource: 255.255.255.255:1280 Destination: 217.208.65.7:syslog(514) Reason: Network Control Rule ID = 65519
Date/Time :2006-12-18 12:09:14Severity :MediumReporter :Network MonitorDescription: Outbound Policy Violation (Access Denied, IP = 217.208.67.68, Port = syslog(514))Protocol: UDP OutgoingSource: 255.255.255.255:1280 Destination: 217.208.67.68:syslog(514) Reason: Network Control Rule ID = 65519
Date/Time :2006-12-18 12:09:06Severity :MediumReporter :Application MonitorDescription: Application Access Denied (svchost.exe:255.255.255.255:bootp(67))Application: C:\WINDOWS\system32\svchost.exeParent: C:\WINDOWS\system32\services.exeProtocol: UDP OutDestination: 255.255.255.255:bootp(67)
Date/Time :2006-12-18 12:09:04Severity :MediumReporter :Network MonitorDescription: Outbound Policy Violation (Access Denied, IP = 217.208.67.43, Port = syslog(514))Protocol: UDP OutgoingSource: 255.255.255.255:1280 Destination: 217.208.67.43:syslog(514) Reason: Network Control Rule ID = 65519
Date/Time :2006-12-18 12:09:04Severity :MediumReporter :Network MonitorDescription: Outbound Policy Violation (Access Denied, IP = 217.208.67.178, Port = syslog(514))Protocol: UDP OutgoingSource: 255.255.255.255:1280 Destination: 217.208.67.178:syslog(514) Reason: Network Control Rule ID = 65519
Date/Time :2006-12-18 12:08:58Severity :MediumReporter :Application MonitorDescription: Application Access Denied (svchost.exe:255.255.255.255:bootp(67))Application: C:\WINDOWS\system32\svchost.exeParent: C:\WINDOWS\system32\services.exeProtocol: UDP OutDestination: 255.255.255.255:bootp(67)